CVE-2026-23455
netfilter: nf_conntrack_h323: check for zero length in DecodeQ931()
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
9th
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() In DecodeQ931(), the UserUserIE code path reads a 16-bit length from the packet, then decrements it by 1 to skip the protocol discriminator byte before passing it to DecodeH323_UserInformation(). If the encoded length is 0, the decrement wraps to -1, which is then passed as a large value to the decoder, leading to an out-of-bounds read. Add a check to ensure len is positive after the decrement.
| Vendor | linux |
| Product | linux |
| Ecosystems | |
| Industries | Technology |
| Published | Apr 3, 2026 |
| Last Updated | Apr 13, 2026 |
Stay Ahead of the Next One
Get instant alerts for linux linux
Be the first to know when new unknown vulnerabilities affecting linux linux are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Linux / Linux
5e35941d990123f155b02d5663e51a24f816b6f3 < 495e97af9e7249ee02b72bb1d0848a6efc3700f4 5e35941d990123f155b02d5663e51a24f816b6f3 < f5e4f4e4cdb75ec36802059a94195a31f193da60 5e35941d990123f155b02d5663e51a24f816b6f3 < 633e8f87dad32263f6a57dccdb873f042c062111 5e35941d990123f155b02d5663e51a24f816b6f3 < 9d00fe7d6d7c5b5f1065a6e042b54f2e44bd6df8 5e35941d990123f155b02d5663e51a24f816b6f3 < b652b05d51003ac074b912684f9ec7486231717b 5e35941d990123f155b02d5663e51a24f816b6f3 < f173d0f4c0f689173f8cdac79991043a4a89bf66
Linux / Linux
2.6.17
References
git.kernel.org: https://git.kernel.org/stable/c/495e97af9e7249ee02b72bb1d0848a6efc3700f4 git.kernel.org: https://git.kernel.org/stable/c/f5e4f4e4cdb75ec36802059a94195a31f193da60 git.kernel.org: https://git.kernel.org/stable/c/633e8f87dad32263f6a57dccdb873f042c062111 git.kernel.org: https://git.kernel.org/stable/c/9d00fe7d6d7c5b5f1065a6e042b54f2e44bd6df8 git.kernel.org: https://git.kernel.org/stable/c/b652b05d51003ac074b912684f9ec7486231717b git.kernel.org: https://git.kernel.org/stable/c/f173d0f4c0f689173f8cdac79991043a4a89bf66